Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
Alerts on Azure AD risk events indicating user credentials were leaked (riskEventType: leakedCredentials).
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh152Free2023-09-03Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders
Alerts on Azure risk events for suspicious inbox rules that delete or move mailbox items.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh161Free2023-09-03Azure Risk Event: Suspicious Inbox Forwarding
Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh335Free2023-09-03Azure AD User Login Risk: Impossible Travel from Distant Locations
Flags Azure Entra risk events tagged as impossibleTravel indicating implausible geographic sign-in travel within a short time.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh91Free2023-09-03Azure Entra ID Identity Protection Unlikely Travel Risk Events
Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh162Free2023-09-03Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh2410Free2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh121Free2023-09-03Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.
Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh82Free2023-08-22Azure risk detection: anomalousToken risk events
Flags Azure Entra ID risk events indicating anomalous token lifetime or use from unfamiliar locations.
Mark Morowczynski '@markmorow', Huntrule TeamAzureriskdetectionHigh122Free2023-08-07AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh131Free2023-05-17AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh123Free2023-05-17AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh481Free2023-05-17Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh172Free2023-03-20Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh90Free2023-01-10Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
Janantha Marasinghe, Huntrule TeamAzuresigninlogsHigh81Free2022-11-27